GRC Engineer - Platform Team

Taktile

United States

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity
Cash compensation
Self-development budget
Home office equipment

Job summary

Taktile, a security-focused SaaS provider for financial services, seeks a GRC Engineer on the Platform Team to own controls and evidence for SOC 2, ISO 27001, GDPR and the EU AI Act. This role partners across Security, Engineering, Product, and IT to turn policy into automated, audit-ready controls.

The ideal candidate combines deep framework knowledge with hands-on automation, scripting AWS evidence collection, and strong cross-team communication to keep us compliant year-round.

Qualifications

  • 4+ years in GRC, security compliance, or audit readiness at a SaaS company.
  • Owned a SOC 2 program end-to-end; familiarity with ISO 27001, GDPR, PCI DSS, EU AI Act.
  • Experience with Vanta/Drata/Secureframe as continuous compliance backbone.
  • Hands-on scripting against AWS APIs to automate evidence collection.
  • Strong writing and communication to translate between compliance and technical teams.

Responsibilities

  • Own continuous compliance end-to-end; SOC 2, ISO 27001, and customer security reviews.
  • Manage and evolve the compliance roadmap; own Vanta end-to-end tasks and integrations.
  • Lead quarterly access reviews across systems; track remediation.
  • Run vendor risk reviews and DPAs for new tools, especially AI tooling.
  • Serve as technical voice on customer security questionnaires and DPAs.
  • Define and report compliance and risk KPIs to leadership.
  • Partner with Security Architect to close gaps between policy and control implementations.

Skills

SOC 2
ISO 27001
GDPR knowledge
Automation scripting
AWS evidence collection
Cross-functional collaboration
Technical writing

Tools

Vanta
Drata
Secureframe

Job description

About the Role

Taktile empowers financial institutions to transform into truly AI-native organizations. We’re growing rapidly with enterprise customers across banks and insurance companies, and we’re looking for a GRC Engineer.

Operating in highly regulated markets means trust isn't a feature for us, it's the foundation of every customer relationship. As we scale into larger enterprise and fintech accounts, a strong, demonstrable security and compliance posture is what lets us win and keep that trust.

As our GRC Engineer on the Platform Team, you'll own the controls, evidence, and processes that keep Taktile secure, compliant, and continuously audit-ready. You'll be the engineering-minded backbone of our compliance program, turning frameworks like SOC 2, ISO 27001, GDPR, and the EU AI Act into automated, continuously-monitored controls rather than one-off, point-in-time checklists.

This is a cross-functional, high-leverage role. You'll partner with Security, Engineering, Product, and IT to close the gap between policy and control implementation, and with Sales, Legal, Support, and Leadership to make compliance a competitive advantage rather than a bottleneck.

The ideal candidate pairs deep framework knowledge with the technical ability to automate it; fielding a complex customer security questionnaire in the morning and scripting AWS evidence collection in the afternoon.

What you'll do
  • Own continuous compliance end-to-end ; SOC 2, ISO 27001, and customer security reviews, keeping us audit-ready year-round rather than scrambling at renewal time.
  • Manage and evolve the compliance roadmap, prioritizing initiatives against business and customer needs; own Vanta end-to-end, including tasks, documentation, integrations, and automated evidence collection.
  • Lead quarterly access reviews across all systems in collaboration with IT and Engineering, ensuring findings are tracked through to remediation.
  • Run vendor risk reviews and DPIAs for new tools (especially AI tooling) and help teams adopt new software quickly without compromising our risk posture.
  • Serve as the technical voice on customer security questionnaires and DPAs, working alongside Sales and Legal to keep deals moving.
  • Define and report compliance and risk KPIs to leadership, giving them a clear, ongoing view of our posture and where investment is needed.
  • Partner with the Security Architect to identify and close gaps between written policy and actual control implementation.
Requirements
  • 4+ years in GRC, security compliance, or audit readiness at a SaaS company, ideally in a regulated environment (Finance, Insurance, Healthcare).
  • Has owned a SOC 2 program end-to-end (must-have), ideally ISO 27001 too, from gap analysis through audit and maintenance; familiar with GDPR, PCI DSS, and the EU AI Act.
  • Deep experience running Vanta (or Drata/Secureframe) as a continuous compliance backbone, not a point-in-time checklist.
  • Technically hands-on: comfortable scripting against AWS APIs to automate evidence collection, with a solid grasp of software development and security concepts.
  • A strong writer and communicator who can turn around a 200-row security questionnaire quickly and accurately, and translate fluently between compliance and technical teams.
Ideal, but not required
  • Experience with customer trust programs (Trust Center, FAQs, security whitepapers).
  • DORA / EU AI Act / fintech regulatory exposure.
  • Has shipped engineering-led automation (not just dashboards).
  • Familiarity with NIST CSF, CIS Controls, or GDPR/DPAs.
What We Offer
  • Work with colleagues that lift you up, challenge you, celebrate you and help you grow. We come from many different backgrounds, but what we have in common is the desire to operate at the very top of our fields. If you are similarly capable, caring, and driven, you'll find yourself at home here.
  • Make an impact and meaningfully shape an early-stage company.
  • Experience a truly flat hierarchy and communicate directly with founding team members. Having an opinion and voicing your ideas is not only welcome but encouraged, especially when they challenge the status quo.
  • Learn from experienced mentors and achieve tremendous personal and professional growth. Get to know and leverage our network of leading tech investors and advisors around the globe.
  • Receive a top-of-market equity and cash compensation package.
  • Get access to a self-development budget you can use to e.g. attend conferences, buy books or take classes.
  • Use the equipment of your choice including meaningful home office set-up.
Our Stance
  • We're eager to meet talented and driven candidates regardless of whether they tick all the boxes. We're looking for someone who will add to our culture, not just fit within it. We strongly encourage individuals from groups traditionally underestimated and underrepresented in tech to apply.
  • We seek to actively recognize and combat racism, sexism, ableism and ageism. We embrace and support all gender identities and expressions, and celebrate love in its many forms. We won't inquire about how you identify or if you've experienced discrimination, but if you want to tell your story, we are all ears.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Lead
Security Lead

Taktile • United States

On-site
USD 180,000 - 260,000
Equity package
Competitive compensation
Self-development budget
+1
Governance, Risk and Compliance Lead
Governance, Risk and Compliance Lead

Thinkingmachines • San Francisco (CA)

On-site
USD 225,000 - 350,000
Health, dental, and vision benefits
Unlimited PTO
Parental leave
+1
GRC Engineer
GRC Engineer

Treasure AI • United States

On-site
USD 140,000 - 210,000
Comprehensive medical, dental, vision
401K with company match
RSU
+2
GRC Manager
GRC Manager

Valence • United States

Hybrid
USD 130,000 - 190,000
WFH stipend
Phone stipend
Workspace support
Governance, Risk and Compliance Lead
Governance, Risk and Compliance Lead

Doist • San Francisco (CA)

On-site
USD 225,000 - 350,000
Health benefits
Dental benefits
Vision benefits
+3
GRC Program Manager, Product and Customer Trust
GRC Program Manager, Product and Customer Trust

OpenAI • San Francisco (CA)

On-site
USD 120,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+4
Director, GRC & Privacy Security
Director, GRC & Privacy Security

Jobtailor • New York (NY)

On-site
USD 130,000 - 160,000
Competitive salary & equity
Unlimited PTO
Full Health, Vision, & Dental coverage
+2
Governance, Risk, and Compliance Manager
Governance, Risk, and Compliance Manager

TensorWave • Las Vegas (NV)

On-site
USD 140,000 - 190,000
Stock Options
Medical Insurance
Dental Insurance
+7
Senior GRC Engineer, Trust
Senior GRC Engineer, Trust

Chainalysis • Virginia (MN), New York (NY)

On-site
USD 120,000 - 190,000
Governance, Risk, and Compliance Manager
Governance, Risk, and Compliance Manager

TensorWave Inc. • Las Vegas (NV)

On-site
USD 120,000 - 180,000
Stock Options
Medical Insurance
Dental Insurance
+10